VendorsNextcloudrichdocumentsany version
Vulnerabilities

Nextcloud Richdocuments any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-37628
File Drop can be bypassed using Richdocuments app in nextcloud
Published 2021-09-07 · Modified
7.5EPSS 0.021
CVE-2023-28645
Secure view can be bypassed by using internal API endpoint in Nextcloud richdocuments
Published 2023-03-31 · Modified
6.5EPSS 0.007
CVE-2022-31024
Federated editing allows iframing remote servers by default in richdocuments
Published 2022-06-02 · Modified
6.5EPSS 0.006
CVE-2023-25150
Document content of files can be obtained through Collabora for files of other users
Published 2023-02-08 · Modified
5.8EPSS 0.007
CVE-2021-37629
Lack of ratelimit on Richdocuments OCS endpoint in nextcloud
Published 2021-09-07 · Modified
5.3EPSS 0.014
CVE-2021-39223
File path disclosure of shared files in Richdocuments application
Published 2021-10-25 · Modified
5.3EPSS 0.011
CVE-2023-25159
Nextcloud Server previews are accessible without a watermark
Published 2023-02-13 · Modified
5.3EPSS 0.005
CVE-2021-32748
WOPI API not protected by credentials/IP check
Published 2021-07-27 · Modified
4.3EPSS 0.010